PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-31357 Growatt CVE debrief

CVE-2025-31357 is an unauthenticated information disclosure issue in Growatt cloud applications. According to CISA’s CSAF advisory, an attacker who knows a username can obtain that user’s plant list in Growatt cloud portal versions up to 3.6.0. The issue is scored CVSS 3.1 5.3 (Medium) and is limited to confidentiality impact in the supplied vector. CISA’s advisory says the cloud-based vulnerabilities were patched and that no user action is needed for the fix, while also recommending standard account-hardening and security-hygiene steps.

Vendor
Growatt
Product
Cloud portal
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2025-04-15
Original CVE updated
2025-05-06
Advisory published
2025-04-15
Advisory updated
2025-05-06

Who should care

Organizations and individuals using Growatt cloud portal, especially administrators and installers managing customer plants, should care. Because the issue is unauthenticated and username-based, teams should treat any exposed Growatt cloud account data as potentially retrievable by a remote party.

Technical summary

The supplied advisory describes a remote, unauthenticated disclosure condition in Growatt cloud portal (affected version range: <= 3.6.0). Knowing a valid username is sufficient to retrieve a user’s plant list. The published CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) indicates network reachability with no privileges required, no user interaction, and confidentiality impact only.

Defensive priority

Medium. The issue is easy to reach remotely and requires no authentication, but the documented impact is limited to confidentiality and the vendor states the cloud-side fix has been applied. Prioritize review if you operate Growatt cloud portal accounts or have sensitive operational plant data exposed through the service.

Recommended defensive actions

  • Confirm whether any organization accounts use Growatt cloud portal versions at or below 3.6.0 and verify the vendor-applied fix is present.
  • Review account and plant-list access patterns for unexpected lookups or abnormal usage tied to known usernames.
  • Use strong passwords and enable multi-factor authentication where applicable, consistent with Growatt’s guidance.
  • Continue to monitor user and installer accounts for unusual activity and report concerns to Growatt [email protected].
  • Apply general ICS security best practices and defense-in-depth measures from CISA resources when managing connected cloud services.

Evidence notes

This debrief is based on the supplied CISA CSAF advisory for ICSA-25-105-04 and the CVE record metadata provided in the source corpus. The advisory explicitly states: “An unauthenticated attacker can obtain a user's plant list by knowing the username.” The affected product entry is “Growatt cloud portal: <=3.6.0.” The revision history shows an initial publication on 2025-04-15 and a later revision on 2025-05-06 for typo fixes. No KEV listing was provided in the corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-31357 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-31357

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-31357 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-31357

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-105-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-105-04

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.